Eclipse ThreadX NetX Duo: 20 Network Protocol Flaws Disclosed Together, Ranging to Critical
Eclipse ThreadX NetX Duo: 20 vulnerabilities disclosed, impacting MQTT, TLS/DTLS, FTP, and other network protocols, with severities up to Critical.

Key findings
- 20 vulnerabilities disclosed in Eclipse ThreadX NetX Duo between Sept 29-30, 2026.
- Flaws span multiple protocols including MQTT, TLS/DTLS, FTP, TFTP, DHCP, MSRP, SNMP, RTSP, mDNS, and ICMPv6.
- Vulnerabilities include out-of-bounds reads, memory disclosure, denial-of-service, and NULL pointer dereferences.
- Critical and High severity flaws present, impacting system stability and security.
- Users urged to consult vendor advisories for patching and mitigation details.
On September 29-30, 2026, a significant batch of 20 vulnerabilities was disclosed in Eclipse ThreadX's NetX Duo, a widely used real-time operating system networking stack. These vulnerabilities, spanning multiple components and protocols, range in severity from Medium to Critical, with a notable cluster of High-severity flaws. The disclosures highlight potential risks including memory disclosure, denial-of-service conditions, and out-of-bounds reads, underscoring the importance of timely patching for embedded systems.
Several vulnerabilities stem from improper handling of network packet data and message parsing across various protocols. CVE-2026-102762 and CVE-2026-102761, both related to the MQTT protocol, can lead to memory leaks or crashes due to malformed messages and incorrect handling of chained packets. The NetX Secure TLS/DTLS components are also affected, with CVE-2026-102728 detailing out-of-bounds reads in handshake parsers, and CVE-2026-102719 pointing to predictable DTLS HelloVerifyRequest cookies. CVE-2026-102712 describes an out-of-bounds read in the initial DTLS ClientHello parsing due to incorrect length validations.
Other protocols are also impacted. The FTP service is vulnerable via CVE-2026-102727, which allows passive data connections to be established without proper binding to the authenticated control peer, and CVE-2026-102722, where the FTP client accepts arbitrary addresses in server replies. The TFTP protocol is affected by CVE-2026-102721 and CVE-2026-102713, leading to out-of-bounds reads or potential issues due to unvalidated datagram sizes. The DHCP client is susceptible to an out-of-bounds read via CVE-2026-102720 due to improper parsing of options.
Further issues include an unbounded PPP IPCP option parsing vulnerability (CVE-2026-102726) causing worker stalls and out-of-bounds reads, and multiple vulnerabilities in the MSRP component: CVE-2026-102725 for out-of-bounds reads from unvalidated attribute list lengths, and CVE-2026-102723 and CVE-2026-102724 for NULL pointer dereferences during attribute table exhaustion or eviction. The SNMP addon is affected by CVE-2026-102718, where an attacker can exploit BER multibyte length encoding to cause buffer overflows. Additionally, CVE-2026-102716 describes how an unauthenticated RTSP client can drain the server's packet pool, and CVE-2026-102715 details an out-of-bounds write in the mDNS responder. Finally, CVE-2026-102714 highlights an issue in ICMPv6 option validation leading to potential unexamined data. CVE-2026-102717, a high-severity flaw, involves an MQTT WebSocket setter ABI mismatch that could disclose memory or cause a crash.
The majority of these vulnerabilities were disclosed on September 29, 2026, with a few extending into September 30. While specific patch details or vendor advisories were not provided in the input, users of NetX Duo are strongly advised to consult Eclipse ThreadX's official security bulletins for affected versions and mitigation strategies. The broad range of affected protocols and components indicates a need for comprehensive security reviews and prompt application of available updates to protect embedded systems from potential exploitation.
Given the number and variety of vulnerabilities, a systematic approach to patching is recommended, prioritizing those with higher severity ratings or those affecting internet-facing services. Continuous monitoring for updated security advisories from Eclipse ThreadX is crucial for maintaining the security posture of NetX Duo deployments.
The disclosed vulnerabilities collectively represent a significant security event for NetX Duo users, emphasizing the ongoing need for vigilance in securing embedded systems against diverse network-based threats.
CVE-2026-102717, CVE-2026-102762, CVE-2026-102761, CVE-2026-102759, CVE-2026-102728, CVE-2026-102727, CVE-2026-102726, CVE-2026-102725, CVE-2026-102724, CVE-2026-102723, CVE-2026-102722, CVE-2026-102721, CVE-2026-102720, CVE-2026-102719, CVE-2026-102718, CVE-2026-102716, CVE-2026-102715, CVE-2026-102714, CVE-2026-102713, CVE-2026-102712